Function App: Fails Validation During Same-Subscription Resource Group Move — ResourceMoveProviderValidationFailed

Agustin Cano 40 Reputation points
2026-09-30T22:57:21.8133333+00:00

Problem description

I am trying to move a Linux Function App within the same subscription from one resource group to another, but the move fails validation with the error ResourceMoveProviderValidationFailed. The validation indicates that certain certificates must be included in the move request, but I am unsure how to proceed given that there are no active hostname or SSL bindings on the app.

Environment

Service: Function App; Resource type: Microsoft.Web/sites; Region: not specified in the case information.

What I've already tried

I have reviewed the case details and diagnostic information provided. I attempted to include the indicated certificates in the move validation process, but I am uncertain about the correct resources to include or how to proceed with the validation.

Current status

I am seeking guidance on how to successfully validate and perform the move of my Function App within the same subscription, specifically regarding the certificate dependencies and validation process.

Azure Functions
Azure Functions

An Azure service that provides an event-driven serverless compute platform.


1 answer

Sort by: Newest
  1. Divyesh Govaerdhanan 11,890 Reputation points MVP Volunteer Moderator
    2026-09-30T23:19:25.56+00:00

    Hello Agustin Cano,

    Welcome to Microsoft Q&A,

    This happens because of a leftover certificate resource in the source resource group, not because of your app's current bindings.

    Even with no hostname or SSL bindings active today, a Microsoft.Web/certificates resource (an uploaded/imported TLS certificate, or a free App Service Managed Certificate) can still exist in the resource group from an earlier setup. Azure requires all App Service related resources in a resource group to move together, so the validation pulls that orphaned certificate into the move request.

    The key detail that trips people up: certificate resources have different move support depending on scope. Per Microsoft's resource move support table, Microsoft.Web/certificates supports moving across subscriptions but not across resource groups, and managed certificates (the free ones) support neither. So if that leftover certificate is sitting in your source resource group, the resource-group move will keep failing validation no matter what you do, until the certificate is out of the picture.

    Steps to fix it:

    1. In the Azure Portal, go to your source resource group and turn on Show hidden types in the resource list (or in the move blade itself). This reveals certificate resources that don't show up by default.
    2. Check what type of certificate it is:
      • If it is a free App Service Managed Certificate, delete it. It cannot be moved to any resource group or subscription. Recreate it in the destination resource group later if you set up a custom domain again.
        • If it is an uploaded or imported certificate, back it up (export the PFX) if you will need it again, then delete it from the source resource group. It cannot move resource group to resource group in the same subscription, only across subscriptions, so deleting and re-uploading in the destination is the workaround.
        1. Retry the move. With the certificate resource gone, only the sites and server farm remain, both of which support resource group moves, so validation should pass.
        2. Re-upload or recreate the certificate in the destination resource group afterward if you still need it bound to a custom domain.

    Reference: Move App Service resources to a new resource group or subscription, Azure resource types for move operations – Microsoft.Web

    Please click Accept Answer and upvote if this helped.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.